Skip to content

Conversation

@Dindexx
Copy link
Contributor

@Dindexx Dindexx commented Nov 19, 2025

Short description of what this resolves:

Adds validation of DC-API origin to prevent session fixation.

Changes proposed in this pull request:

Fixes: #

@Dindexx Dindexx requested a review from JoTiTu November 19, 2025 14:36
@Dindexx Dindexx self-assigned this Nov 19, 2025
Copy link
Contributor

@JoTiTu JoTiTu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Dindexx Dindexx merged commit b47bb75 into v3.0.0 Nov 20, 2025
2 checks passed
Dindexx added a commit that referenced this pull request Nov 20, 2025
* DC-API: Validate origin

Signed-off-by: Kevin <[email protected]>

* DC-API: refactor

Signed-off-by: Kevin <[email protected]>

---------

Signed-off-by: Kevin <[email protected]>
Dindexx added a commit that referenced this pull request Nov 20, 2025
* Migrate storage layer to EF Core

Signed-off-by: Kevin <[email protected]>

* deprecate aries and indy (#427)

Signed-off-by: Kevin <[email protected]>

* Align IssuerMetadata with VCI 1.0 spec (#438)

* support credential_metadata in issuer metadata and drop AttributeOrder support

Signed-off-by: Johannes Tuerk <[email protected]>

* clean attribute order

Signed-off-by: Johannes Tuerk <[email protected]>

* Merge branch 'v3.0.0' of github.com:openwallet-foundation-labs/wallet-framework-dotnet into algin-isser-metadata-with-oid4vci1.0

Signed-off-by: Johannes Tuerk <[email protected]>

* Add CredentialsSet id as index to SdJwt and MDoc records

Signed-off-by: Johannes Tuerk <[email protected]>

* Fix the issuance for the PID (associate SdJwt AND MDocs with PID)

Signed-off-by: Johannes Tuerk <[email protected]>

* implement requested changes

Signed-off-by: Johannes Tuerk <[email protected]>

* minimal cleanup

Signed-off-by: Kevin <[email protected]>

* Revert Vctmetadata ClaimDisplay removal

Signed-off-by: Johannes Tuerk <[email protected]>

---------

Signed-off-by: Johannes Tuerk <[email protected]>
Signed-off-by: Kevin <[email protected]>
Co-authored-by: Kevin <[email protected]>
Signed-off-by: Kevin <[email protected]>

* adjust readme for deprecating indy (#439)

Signed-off-by: Kevin <[email protected]>

* adjustment for indy migration (#450)

Signed-off-by: Kevin <[email protected]>

* Fix supported algs for the issuer signed jwt in wallet metadata (#449)

Signed-off-by: Johannes Tuerk <[email protected]>
Signed-off-by: Kevin <[email protected]>

* fix tests

Signed-off-by: Kevin <[email protected]>

* make dependencies packable again

Signed-off-by: Kevin <[email protected]>

* DC-API: Validate origin

Signed-off-by: Kevin <[email protected]>

* Introduce SDLC (#466)

* initial sdcl introduction

Signed-off-by: Johannes Tuerk <[email protected]>

* add TODO

Signed-off-by: Johannes Tuerk <[email protected]>

* sign git tag

Signed-off-by: Johannes Tuerk <[email protected]>

* update sdlc guide

Signed-off-by: Johannes Tuerk <[email protected]>

---------

Signed-off-by: Johannes Tuerk <[email protected]>
Signed-off-by: Kevin <[email protected]>

* Dc api validate origin (#473)

* DC-API: Validate origin

Signed-off-by: Kevin <[email protected]>

* DC-API: refactor

Signed-off-by: Kevin <[email protected]>

---------

Signed-off-by: Kevin <[email protected]>

---------

Signed-off-by: Kevin <[email protected]>
Signed-off-by: Johannes Tuerk <[email protected]>
Co-authored-by: Johannes Tuerk <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants